
nmap
High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

E-mails, subdomains and names Harvester - OSINT

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

Directory/File, DNS and VHost busting tool written in Go

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

In-depth attack surface mapping and asset discovery

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Generates permutations, alterations and mutations of subdomains and then resolves them

Modular OSINT framework for gathering intelligence on domains, usernames, phone numbers, and emails using public sources, Google dorks, and…

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and…

A DNS meta-query spider that enumerates DNS records, and subdomains.

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

Find domains and subdomains related to a given domain

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…